github / github/github-ospo

Automation to enforce repository permissions are by github team only and not individuals

未關閉
#86 2 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
enhancement new-action
主要語言
沒有語言資料
星號
749
分支
72
PR 合併指標
30 天內沒有已合併 PR

描述

### Is your feature request related to a problem?

To ensure that permissions are easier to maintain and keep updated, its a best practice to give permission to a GitHub team and then instead of removing them from a large number of repos, you can just remove them from the team. Well maintained permissions improves security posture.

The task here would be to create a/utilize an existing GitHub action or App to accomplish this.

貢獻指南

開啟貢獻指南

研究方向

尚未識別任何檔案或測試。首先比較 GitHub Action 與 GitHub App,以強制執行僅限團隊的儲存庫權限,接著定義如何處理現有的個人權限,以及哪些儲存庫屬於範圍內。完成的標準是:所選的自動化能夠強制執行規則或回報違規情況,且其預期行為已有文件說明。

由索引模型根據 Issue 內容生成。

評估

技術堆疊
github, github-actions
領域
devops, security
Issue 類型
功能
難度
5/5
預估耗時
一週以上
活躍度
停滯
描述清晰度
基本清楚
新手友好度
35/100

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。